Ahmed Abdulghani Ali, Farhan Khalid, Jabbar Waheb A, Al-Othmani Abdulaleem, Abdulrahman Abdullahi Gara
School of Computer Science and Informatics, De Montfort University, The Gateway, Leicester LE1 9BH, UK.
School of Computer Science and Engineering, University of New South Wales, Sydney 2164, Australia.
Sensors (Basel). 2024 Aug 12;24(16):5210. doi: 10.3390/s24165210.
The Internet of Things forensics is a specialised field within digital forensics that focuses on the identification of security incidents, as well as the collection and analysis of evidence with the aim of preventing future attacks on IoT networks. IoT forensics differs from other digital forensic fields due to the unique characteristics of IoT devices, such as limited processing power and connectivity. Although numerous studies are available on IoT forensics, the field is rapidly evolving, and comprehensive surveys are needed to keep up with new developments, emerging threats, and evolving best practices. In this respect, this paper aims to review the state of the art in IoT forensics and discuss the challenges in current investigation techniques. A qualitative analysis of related reviews in the field of IoT forensics has been conducted, identifying key issues and assessing primary obstacles. Despite the variety of topics and approaches, common issues emerge. The majority of these issues are related to the collection and pre-processing of evidence because of the counter-analysis techniques and challenges associated with gathering data from devices and the cloud. Our analysis extends beyond technological problems; it further identifies the procedural problems with preparedness, reporting, and presentation as well as ethical issues. In particular, it provides insights into emerging threats and challenges in IoT forensics, increases awareness and understanding of the importance of IoT forensics in preventing cybercrimes, and ensures the security and privacy of IoT devices and networks. Our findings make a substantial contribution to the field of IoT forensics, as they not only involve a critical analysis of the challenges presented in existing works but also identify numerous problems. These insights will greatly assist researchers in identifying appropriate directions for their future research.
物联网取证是数字取证领域中的一个专业领域,专注于识别安全事件,以及收集和分析证据,目的是防止未来对物联网网络的攻击。由于物联网设备具有独特的特性,如处理能力和连接性有限,物联网取证与其他数字取证领域有所不同。尽管关于物联网取证已有大量研究,但该领域发展迅速,需要进行全面的综述以跟上新发展、新出现的威胁和不断演变的最佳实践。在这方面,本文旨在综述物联网取证的现状,并讨论当前调查技术中存在的挑战。对物联网取证领域的相关综述进行了定性分析,确定了关键问题并评估了主要障碍。尽管主题和方法多种多样,但仍出现了一些常见问题。由于与从设备和云端收集数据相关的反分析技术和挑战,这些问题大多与证据的收集和预处理有关。我们的分析不仅限于技术问题;还进一步确定了准备、报告和展示方面的程序问题以及伦理问题。特别是,它深入探讨了物联网取证中出现的新威胁和挑战,提高了对物联网取证在预防网络犯罪中的重要性的认识和理解,并确保了物联网设备和网络的安全与隐私。我们的研究结果对物联网取证领域做出了重大贡献,因为它们不仅对现有研究中提出的挑战进行了批判性分析,还识别了众多问题。这些见解将极大地帮助研究人员确定未来研究的合适方向。